Malicious AI ‘skills’ turned agents into credential thieves, at scale
Malicious AI ‘skills’ turned agents into credential thieves, at scale

Security researchers at Zenity Labs uncovered a credential-stealing campaign on skills.sh, a public registry of add-ons for AI agents run by Vercel. They unveiled the research at the Black Hat conference. Attackers had cloned real skills into typosquat…

Computer maker Framework notifies ‘all customers’ of a data breach

Framework told “all” of its customers that hackers accessed their names, email addresses, phone numbers, and physical addresses in a data breach.

Top US hedge funds targeted by major vishing campaign — Blackstone, KKR and CME among those under fire

BlackFile (now known as Redact) has been busy, raking in more than $10 milllion since the start of the year.

Chinese AI model Kimi escaped its cybersecurity testing environment, researchers say

In the Kimi test, the sandbox designed to contain the experiment was not properly configured.

Hackers Stalked Me by Hijacking a Smartwatch for Kids

Security researchers tracked and eavesdropped on a WIRED reporter using vulnerabilities in a pink plastic smartwatch. It’s just one piece of a deeply insecure supply chain of GPS-enabled gadgets.

Google says hackers are calling financial firm employees to hack and extort victims

Groups of hackers are breaking into large U.S. financial firms to steal sensitive data and extort victims, Google’s security researchers report.

China-linked LightSpy spyware caught targeting victims in 13 countries, including the US

Researchers linked the latest malicious activity to a Chinese company, after one of the spyware’s operators placed an order with KFC using their real name and office address.